Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

how can i cancle the life time on ipsec

hi

when i do show crypto session detail command i get this following massage:

Interface: FastEthernet0/1

Session status: UP-ACTIVE

Peer: 172.30.102.101/500 fvrf: (none) ivrf: (none)

Phase1_id: 172.30.102.101

Desc: (none)

IKE SA: local 172.30.102.102/500 remote 172.30.102.101/500 Active

Capabilities:D connid:84 lifetime:23:55:29

IPSEC FLOW: permit ip 172.30.102.100/255.255.255.252 172.30.102.100/255.255.25

5.252

Active SAs: 2, origin: crypto map

Inbound: #pkts dec'ed 16 drop 0 life (KB/Sec) 4477653/3329

Outbound: #pkts enc'ed 16 drop 4 life (KB/Sec) 4477653/3329

That mean i have a lifetime with as appear in the example : 23:55:29, and after that time the the ipsec is getting down.

how can i disable this life time,that the ipsec(crypto)work allways.

thanks.

1 REPLY
Hall of Fame Super Silver

Re: how can i cancle the life time on ipsec

Menash

The lifetime of the Security Association is part of the design of IPSec and you can not disable it. The purpose of the lifetime is to periodically force the peers to negotiate new keys. If the peers kept the same key always it would make it easier to crack the encryption but forcing periodic negotiation of new keys helps provide protection for the traffic. You can configure a longer lifetime if you wish, but you can not disable the lifetime.

HTH

Rick

113
Views
0
Helpful
1
Replies
CreatePlease login to create content